CVE-2017-12864High· 8.8▾ TwilightInteger Overflow or Wraparound in OpenCV
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
2.7%
2.7% → 2.7%
Last analysed / modified upstream
In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects OpenCV 3.3 (corresponding with OpenCV-Python version 3.3.0.9) and earlier.
opencv-python < 3.3.1.11opencv-contrib-python < 3.3.1.11Upgrade to a patched release:
opencv-python 3.3.1.11opencv-contrib-python 3.3.1.11Connected by shared product, vendor, weakness, or advisory.
CVE-2017-12863High· 8.8Integer Overflow or Wraparound in OpenCV
CVE-2017-12601High· 8.8Improper Restriction of Operations within the Bounds of a Memory Buffer in OpenCV
CVE-2017-12606High· 8.8Out-of-bounds Write in OpenCV
CVE-2017-12605High· 8.8Out-of-bounds Write in OpenCV
CVE-2017-12602High· 7.5Denial of Service in OpenCV
CVE-2017-1000450High· 8.8Integer Overflow or Wraparound in OpenCV.